gateway_attestation is evidence for the NEAR AI Cloud gateway. It is not evidence for a model environment. Use model attestations when your policy also requires model evidence.
Request gateway evidence
Generate the nonce in your client. It must be 32 random bytes encoded as 64 hexadecimal characters.gateway_attestation. For a deployment-first completion, verify and retain it before sending the completion. Add model=<MODEL_ID>, provider=near, and the x-no-aliasing: true header when you also need NEAR model evidence. That request returns NEAR model reports in model_attestations[]; verify every entry before sending the completion. Add include_tls_fingerprint=true only when you are following the NEAR AI Cloud gateway TLS flow.
Verify the gateway report
Forgateway_attestation:
- Verify
intel_quotewith an Intel DCAP quote verifier, such asdcap-qvl, and apply your TCB and advisory policy. - Read
report_dataand measurements from the verified quote, not only from fields echoed in the HTTP response. Reject the report if its echoedrequest_nonceorreport_datais missing or differs from the nonce and report data you verified. - Check that the verified quote binds the nonce generated by your client and the reported
signing_address. Usesigning_algoto interpret that identity and verify response signatures. - Replay
event_logas described in Replay the RTMR3 event log and require the result to equal the RTMR3 in the verified quote. - Obtain the raw
info.tcb_info.app_composestring. Iftcb_infois JSON text, decode it first. Hashapp_composewithout parsing or reserializing it, and require the quote’s 48-byte MRCONFIGID to equal01, then that SHA-256 hash, then 15 zero bytes. See Check the configuration measurement. - When a TLS fingerprint was requested, verify its binding as part of the NEAR AI Cloud gateway TLS flow.
- Apply your accepted measurement and image-provenance policy.
Field scope
Freshness and failure handling
The nonce establishes freshness only when the client generated and retained it, and the verified quote contains that nonce. If the report is unavailable, the quote fails, the nonce does not match, or the identity does not match, treat the gateway property as unverified. For a deployment-first response-signature flow, retain this verified report and require a latergateway signature to match its signer and algorithm. A report fetched after the completion cannot replace that preflight evidence, and a report from another signer is not a substitute.